Businessnewshubb
Advertisement
  • Home
  • World
  • Business News
  • Markets
  • Startup
  • Contact Us
No Result
View All Result
  • Home
  • World
  • Business News
  • Markets
  • Startup
  • Contact Us
No Result
View All Result
Businessnewshubb
No Result
View All Result
Home Startup

Security researchers warn of a new class of Apple bugs

February 22, 2023


Security researchers say they have uncovered a “new class” of vulnerabilities that could allow attackers to bypass Apple’s security protections in iOS and macOS to access users’ sensitive data.

Trellix’s Advanced Research Center published details this week of the privilege escalation vulnerabilities — meaning they allow someone to gain an elevated level of access to the system — affecting both iPhones and Macs. Trellix warned that the class of bugs, which range from medium to high severity, could — if left unpatched — allow malicious apps to escape their protective “sandbox” and access sensitive information on someone’s device, including a person’s messages, location data, call history, and photos.

Trellix’s findings follow earlier research from Google and Citizen Lab, which in 2021 discovered a new zero-day exploit dubbed ForcedEntry that was abused by Israeli spyware maker NSO Group to remotely and stealthily hack into iPhones at the behest of its government customers. Apple subsequently strengthened its device security protections by adding in new code-signing mitigations, which cryptographically verify that the device’s software is trusted and hasn’t been modified, to stop the exploitation of the exploit.

But Trellix said this week that the mitigations put in place by Apple are insufficient to prevent similar attacks.

In a blog post, Trellix said the new bugs involve NSPredicate, a tool that allows developers to filter code, around which Apple tightened restrictions following the ForcedEntry bug through a protocol called NSPredicateVisitor. But Trellix said that nearly every implementation of NSPredicateVisitor “could be bypassed.”

While Trellix has seen no evidence to suggest that these vulnerabilities have been actively exploited, the cybersecurity company tells TechCrunch that its research shows that iOS and macOS are “not inherently more secure” than other operating systems.

“The vulnerabilities uncovered by our team this week have fundamentally broken their security model,” said Doug McKee, director of Vulnerability Research at Trellix, adding that the bugs could have, in theory, exposed affected Apple devices to a wide range of attack vectors and made it easier for improper access to sensitive data. “These bugs essentially allow an attacker that has achieved low privileged code execution, i.e., basic functions on macOS or iOS, to gain much higher privileges.”

Apple patched the vulnerabilities Trellix found in its macOS 13.2 and iOS 16.3 software updates, released in January. Apple’s security support documents were also updated on Tuesday to reflect the release of the new patches.

Will Strafach, a security researcher and founder of the Guardian firewall app, described the vulnerabilities as “pretty clever,” but warned that there is little the average user can do about these threats, “besides staying vigilant about installing security updates.”

iOS and macOS security researcher Wojciech Reguła told TechCrunch that while the vulnerabilities could be significant, in the absence of exploits, more details are needed to determine how big this attack surface is.

Jamf’s Michael Covington said that Apple’s code-signing measures were “never intended to be a silver bullet or a lone solution” for protecting device data. “The vulnerabilities, though noteworthy, show how layered defenses are so critical to maintaining good security posture,” Covington said.

When reached, Apple did not provide an on-the-record comment.



Source link

Previous Post

AAVAA closes $2 million CAD to develop smart listening device

Next Post

Former Cohasset High School Employee Accused of Stealing Thousands in Electricity to Mine Bitcoin in School Campus Crawlspace – Bitcoin News

Next Post

Former Cohasset High School Employee Accused of Stealing Thousands in Electricity to Mine Bitcoin in School Campus Crawlspace – Bitcoin News

Hit It & Quit It with LaQuan McCarley, Meredith Bell, & Vernon L. Williams » Succeed As Your Own Boss

Croptimistic acquires CropPro Consulting, secures $9.1 million from Forage Capital

Google rolls out tests that block news content for some users in Canada

Kenyan Senate Ready to Engage Central Bank – Bitcoin News

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Gudi Padwa offers from developers. Should you buy?

by admin
March 21, 2023

Gudi Padwa offers from developers. Should you buy?Despite rising interest rates, on the auspicious day of Gudi Padwa home-buying is...

Instagram is bringing ads to search results and launching ‘Reminder Ads’

by admin
March 21, 2023

Meta is introducing two new tools on Instagram designed to open up additional avenues for advertising as the company grapples...

Haply Robotics secures $4.8 million CAD seed round to develop tactile tech used for surgical training, gaming

by admin
March 21, 2023

Funds will go towards fine-tuning Haply’s Inverse3 device. Montréal-based Haply Robotics has secured $4.8 million CAD ( $3.5 million USD)...

Crystal Blockchain Study Reveals $16.7 Billion in Crypto Assets Stolen Since 2011 – Bitcoin News

by admin
March 21, 2023

Crystal Blockchain, a company that provides blockchain data and analytics, published a study covering security breaches, fraud, and scams related...

business-news-hubb-white

© 2022 Business News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Categories

  • Home
  • World
  • Business News
  • Markets
  • Startup
  • Contact Us

Newsletter Sign Up.

No Result
View All Result
  • Home
  • World
  • Business News
  • Markets
  • Startup
  • Contact Us

© 2022 Business News Hubb All rights reserved.